Iranian-linked intruders are no longer merely entering American industrial systems. They are changing the instructions that govern physical processes, disabling the alarms meant to expose unsafe conditions and manipulating the displays operators rely upon to distinguish normal operation from an approaching crisis.
By Jonathan Lockhart
Imagine an operator seated before a row of industrial displays. The pumps are running. Pressure appears stable. The process diagram remains comfortably green. No alarm is sounding, and nothing on the screen suggests that the machinery beyond the control room is behaving abnormally.
But the display is no longer telling the truth.
Inside a programmable logic controller—the small industrial computer issuing commands to valves, motors, pumps and other equipment—the legitimate program has been altered. Enough of the original logic remains for the process to continue operating. Added instructions quietly override the rules intended to keep that process within safe limits. The alarm that should warn the operator has been disabled. So has the automatic shutdown function that should intervene when conditions become dangerous.
This opening is hypothetical. The underlying capabilities are not.
On July 22, 2026, seven United States government agencies expanded an urgent warning about Iranian-affiliated cyber operations against American critical infrastructure. The FBI and the Cybersecurity and Infrastructure Security Agency reported that intruders had extracted project files from programmable logic controllers, modified or deleted their control logic, manipulated information displayed through industrial monitoring systems and disabled critical alarm and shutdown functions.
At one American victim, investigators found that the attackers had used legitimate engineering software to download a malicious project file to a controller. The modified file retained the ladder logic necessary for downstream equipment to continue functioning, but added instructions that overrode commands responsible for maintaining safe operating parameters.
That is the sentence in the advisory that should stop an industrial operator cold.
The objective was not simply to crash a computer. It was not to encrypt office files, steal employee records or display a political message on a screen. The attackers demonstrated the ability to interfere with the machinery’s governing logic while preserving enough normal behavior to conceal what had changed.
There is no public evidence that these intrusions have yet caused deaths, a major environmental release, widespread power failure or catastrophic equipment destruction. The advisory reports operational disruption and financial loss at some victims, but it does not identify the facilities or describe the physical processes involved. Those evidentiary limits matter.
They do not make the campaign less serious.
This is the boundary at which a cyber intrusion becomes an engineering attack.
The small computers that run the physical world
A programmable logic controller, or PLC, is a ruggedized computer designed to operate machinery reliably for years in environments that would be inhospitable to an ordinary server. PLCs control industrial processes in water plants, electrical systems, factories, pipelines, mines, transportation facilities and countless other settings.
A controller continuously reads inputs from the physical world: temperature, pressure, flow, tank level, motor speed, valve position or the state of a switch. It processes those inputs according to a program and sends outputs to machinery.
If a tank level rises above a specified point, the controller may start a pump. If pressure becomes excessive, it may close a valve. If a motor overheats, it may stop the motor and activate an alarm. In a water facility, the controller may coordinate pumps and chemical-dosing equipment. In manufacturing, it may regulate the timing, movement and temperature of a production line.
The program governing these decisions is often expressed in ladder logic, a graphical language descended from the diagrams once used to describe electromechanical relays. To the untrained eye it can resemble a collection of rails, switches and coils. To an industrial engineer, it describes the conditions under which physical equipment should start, stop, accelerate, open, close or refuse a dangerous command.
The project file contains more than a generic piece of software. It can contain the operating knowledge of a particular facility: device configurations, addresses, reusable function blocks, alarm thresholds, process sequences and the relationships among field equipment.
Stealing that file gives an attacker a map of how a portion of the facility thinks.
Changing it gives the attacker an opportunity to change how the facility behaves.
The federal advisory says Iranian-affiliated operators used legitimate programming applications—including Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert and Siemens’ Totally Integrated Automation Portal—to connect to exposed controllers and remove their project files. These are the same tools engineers use to commission equipment, diagnose problems and update industrial programs.
The presence of legitimate engineering software is important. The intruders did not necessarily need exotic malware running inside every controller. Once an industrial device accepted their connection, the authorized engineering tool could perform the dangerous work for them.
The controller saw an engineering session. The physical process experienced an adversary.
From nuisance attacks to process manipulation
Iranian-linked groups have targeted industrial control systems before.
Beginning in November 2023, the Islamic Revolutionary Guard Corps-linked group commonly called CyberAv3ngers compromised at least 75 Unitronics devices in the United States. Many were used by water and wastewater facilities. Some attacks appeared selected because the equipment was Israeli-made, and the intruders often replaced normal displays with political messages.
Those incidents were serious, but much of the activity looked like opportunistic exploitation of exposed, poorly secured equipment. The attackers could demonstrate access, disrupt operations and generate publicity without necessarily understanding the entire process behind each controller.
The 2026 findings represent a more consequential stage.
Federal investigators now report targeting of Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric BMX P34 and Modicon M340 systems, and Siemens S7-1200 devices. Those product families are used across a broad industrial landscape. The affected organizations include government and municipal facilities, water and wastewater systems, and the energy sector. Other manufacturers may also be targeted.
The campaign began no later than March 2026 and intensified amid conflict involving Iran, Israel and the United States. The government assessment is that the operators intended to cause disruptive effects inside the United States.
The attackers reached internet-facing controllers through foreign infrastructure and common industrial ports. In one case they used Dropbear, a compact Secure Shell service, on a victim’s cellular modem to maintain remote access. They extracted controller programs to systems they controlled, examined or modified the files, and interacted with the machinery through vendor engineering software.
Federal investigators then found changes to project logic, including reusable Rockwell Automation Add-On Instructions. Such modules can be used repeatedly throughout a controller program. A malicious alteration to a reusable block may therefore affect multiple portions of a process while hiding inside code that engineers ordinarily trust.
The government also found data manipulation on human-machine interfaces and supervisory control and data acquisition systems—the screens and larger monitoring platforms through which operators see what the process is doing.
Finally, the changes disabled critical shutdown and alarm logic.
Each step is concerning on its own. Together, they form a recognizable attack on industrial truth.
The project file tells the controller what to do. The controller influences the equipment. The display tells the operator what the equipment is doing. The alarms tell the operator when something has gone wrong. The shutdown logic is supposed to intervene when human reaction is too slow.
An adversary capable of manipulating all four is no longer attacking only a computer network. The adversary is attempting to control the process, the safeguards and the human understanding of events at the same time.
The Stuxnet comparison—and its limits
Stuxnet remains the unavoidable reference point for this kind of operation.
Discovered in 2010, Stuxnet was designed to interfere with centrifuges used in Iran’s uranium-enrichment program. It modified industrial control logic to drive physical equipment beyond its intended operating pattern while feeding operators misleading information that helped conceal the interference. Centrifuges were reportedly destroyed while the larger process appeared, for a time, to be experiencing ordinary reliability problems.
The comparison should be made carefully.
The Iranian-linked activity described in the 2026 advisory has not been shown to possess Stuxnet’s technical sophistication. Stuxnet was a highly engineered, target-specific operation that used multiple vulnerabilities, detailed knowledge of its intended environment and specialized code designed for a particular physical effect. The current advisory describes opportunistic access to exposed or misconfigured controllers, the use of legitimate programming tools and malicious modification of victim project files.
There is no evidence in the public report of a comparably elaborate malware platform. There is no confirmed campaign of precision equipment destruction. There is no public basis for claiming that the attackers can produce any physical outcome they choose against any facility using one of the named controller families.
Yet the strategic resemblance is real.
Both cases concern the deliberate alteration of industrial logic. Both involve interference with the physical process rather than merely the surrounding office network. Both recognize that deception may be more effective than an obvious shutdown. And both exploit a fundamental vulnerability in automated industry: operators must base urgent decisions on information produced by the same digital environment an attacker may be manipulating.
This is Stuxnet-type engineering in the sense that matters most. The target is no longer information alone. The target is the relationship between software, machinery and human perception.
A crude attacker can stop a pump.
A more dangerous attacker can make the pump behave incorrectly.
A still more dangerous attacker can make it behave incorrectly while assuring the operator that everything is fine.
What failure could look like
It would be irresponsible to claim that the documented intrusions prove an imminent ability to poison a city, destroy a power grid or detonate an industrial plant. Industrial systems differ enormously. Many contain mechanical protections, independent safety instruments, relief valves, local controls and trained operators capable of recognizing abnormal conditions outside the primary display system.
It would be equally irresponsible to discuss the campaign as though the only demonstrated consequence were an inconvenient computer outage.
The government has confirmed that attackers placed systems in unsafe conditions while suppressing warnings. Once that capability exists, the possible crises must be examined in physical terms.
At a water-treatment facility, manipulated controller logic could interfere with pumping, filtration, reservoir levels or chemical dosing. The most likely early consequence might not be mass poisoning, as popular imagination tends to leap toward, but loss of confidence in the process. If operators cannot trust chemical readings, valve states or tank levels, they may have to stop production, issue conservation notices, switch to manual operation or advise customers to boil water while samples are tested.
A simultaneous attack on wastewater systems could disable pumps, alter aeration or treatment sequences, and contribute to overflows or untreated releases. Even when independent safeguards prevent a public-health disaster, restoration could take days because engineers would need to determine which controller programs and displayed values remained trustworthy.
In the electrical sector, manipulated control logic could open or close equipment at the wrong time, interfere with cooling or auxiliary systems, disrupt generation processes or produce misleading information about local conditions. The 2015 cyberattack against Ukrainian utilities demonstrated that attackers with remote access to operational systems could disconnect substations and leave approximately 225,000 customers without power. A later attack used purpose-built malware to automate actions against electrical infrastructure.
The present campaign is not proof that Iranian operators can reproduce those events at national scale. It does establish access to the class of equipment from which local physical disruption can begin.
The danger increases when electric power is considered not as an isolated service but as the foundation beneath other services. Water distribution requires electricity. Communications systems depend on electricity and backup fuel. Hospitals can sustain essential functions on generators, but not indefinitely and not without reliable fuel delivery. Traffic control, refrigeration, payment systems, building access, cellular networks and municipal emergency operations all degrade as an outage persists.
A cyberattack that begins at one poorly secured controller can become a civic emergency through ordinary dependency.
In oil, gas and chemical environments, unsafe commands can carry more immediate physical consequences. Incorrect valve positions, pump operation, pressure management or temperature control can damage equipment or contribute to a release. Safety systems are designed to prevent such events, but the 2017 TRISIS attack demonstrated that adversaries have deliberately targeted a petrochemical safety-instrumented system—the independent layer intended to shut a process down before it becomes catastrophic.
The current advisory does not say that Iranian actors compromised an independent safety-instrumented system. It says they disabled critical shutdown and alarm logic within affected project files. That distinction must be preserved. It is nevertheless a warning that attackers understand safeguards as obstacles to be neutralized, not merely features to be avoided.
Manufacturing presents another range of possibilities. A manipulated controller might produce obvious downtime, but it might also create subtler quality failures: an incorrect temperature, pressure, mixture, timing interval or machine tolerance. In food, pharmaceutical or chemical production, the resulting product might require quarantine or recall even if no harmful item reached the public.
The attacker would not need to contaminate a product successfully. Merely creating credible uncertainty about whether production parameters had been falsified could force an organization to discard inventory and shut down a line while it reconstructed events.
That is one of the asymmetric advantages of attacking process integrity. Once the victim can no longer prove that the machinery operated correctly, caution itself becomes costly.
The most dangerous screen in the building
The manipulation of operator displays deserves more attention than it usually receives.
Human-machine interfaces and SCADA systems compress enormous industrial processes into symbols, numbers, colors and alarms that people can interpret quickly. A pump may be represented by an icon. A valve may appear open or closed. A tank is reduced to a percentage. Pressure becomes a number or a moving line.
This abstraction is essential. An operator cannot stand beside every piece of equipment at once.
It also creates a form of dependence. If the screen says a valve is closed, the operator ordinarily cannot see the physical valve from the control room. If the reported pressure is normal, there may be no reason to walk into the facility with a separate instrument and check it. Automation works because people generally trust the signals automation provides.
An attacker who changes the machinery but not the display may be discovered quickly. An attacker who alters both can delay recognition and distort the response.
The operator may increase output when the correct action is to stop. A maintenance team may be sent to the wrong equipment. A supervisor may conclude that an independent sensor is defective because it conflicts with the compromised display. The false information can become more dangerous than the malicious command because it recruits human judgment into sustaining the error.
This is why the answer cannot be limited to better antivirus software or a rule blocking the IP addresses listed in the advisory. Industrial safety depends upon trusted ways to compare cyber-reported conditions with physical reality.
That may include independently wired alarms, mechanical interlocks, local gauges, separate safety controllers, process historians protected from the primary control path and established procedures for verifying critical conditions out of band. None is infallible. Together, they make it harder for one compromised digital view to become the facility’s only source of truth.
The crisis of restoration
A destructive intrusion announces itself. Equipment stops, screens go dark and management begins asking how quickly operations can be restored.
A deceptive intrusion creates a more difficult question: restored from what?
If attackers stole and modified project files, the latest backup may not be safe. If they remained present long enough, multiple generations of backups may contain the malicious logic. If a reusable instruction was altered, engineers must determine everywhere that module was used. If the display layer was manipulated, historical records may no longer provide an unquestionably accurate account of what the process did.
Simply downloading the most convenient backup may reinstall the attacker’s work.
CISA therefore advises operators to compare running programs with known-good logic, validate reusable modules and input-output configurations, and inspect connected modems, engineering workstations and human-machine interfaces for lateral movement. Backups must be examined before restoration. A controller should not be placed into a protected run mode until the project currently loaded into it has been verified, because the mode switch may preserve malicious logic as effectively as legitimate logic.
Recovery may also require physical inspection. Valve positions, tank contents, product quality, safety settings and equipment condition may need to be confirmed independently before operations resume. In some facilities, the safest incident-response decision may be a controlled shutdown—not because the attacker has already caused catastrophe, but because continued operation depends upon information that can no longer be trusted.
This is where a cyber incident can become an extended infrastructure disruption without the attacker having to destroy anything.
An adversary can impose costs by corrupting confidence.
Why exposed controllers still exist
The immediate access route described by the government is almost embarrassingly straightforward: industrial controllers and cellular modems were reachable from the internet without sufficient protection.
That does not mean the people operating them are indifferent to safety.
Industrial environments often contain equipment installed years or decades apart. Remote access may have been added so a small utility could obtain vendor support without dispatching an engineer across a large territory. A cellular modem may connect an isolated pumping station where conventional network service is unavailable. A contractor may have commissioned a device temporarily and never removed the external access. Documentation may be incomplete, and responsibility may be divided among the owner, an integrator, a telecommunications provider and several equipment vendors.
Operational teams also work under constraints unfamiliar to ordinary information technology departments. A server can often be patched and rebooted during a maintenance period. Stopping an industrial controller may interrupt water delivery, halt production or create its own safety risk. An upgrade must be tested against the physical process, not merely against software compatibility.
These are explanations, not excuses for direct internet exposure.
The government’s strongest recommendation is also its simplest: a PLC should not accept unsolicited inbound connections from the public internet. Necessary remote access should be brokered through a monitored gateway or jump host, protected by multifactor authentication and restricted to known systems and users. Cellular connections require the same architectural discipline; they should not be treated as invisible merely because they do not pass through the organization’s conventional firewall.
Communications to controllers should be limited to expected engineering stations and control-system devices. Programming functions should not be available from networks that have no reason to use them. Physical or software mode protections should prevent remote modification during normal operation.
Most importantly, organizations must know what they have. An asset inventory should identify the controller, its purpose, its network path, its firmware, the engineering software authorized to communicate with it and the person responsible for its configuration. A device nobody has inventoried cannot be reliably isolated, monitored or restored.
The wider strategic warning
The campaign may be opportunistic in its selection of exposed equipment, but its political value is larger than the individual devices.
An adversary does not need the ability to turn off an entire nation to influence decisions during a crisis. It may be enough to demonstrate that municipal water systems, energy facilities and local government operations are reachable. A handful of disruptive incidents can create uncertainty about where else access may exist. Authorities must then decide whether each equipment failure is accidental, criminal or part of a coordinated state operation.
That ambiguity consumes time.
Prepositioned access can also become more valuable as geopolitical conditions change. A controller compromised today may be used for reconnaissance, experimentation or intimidation. The stolen project file teaches the attacker about the facility. A later operation can be more selective because the adversary has already learned which instructions control the process and which displays shape the operator’s response.
The July advisory should therefore be read not only as an incident report but as evidence of capability development. Iranian-affiliated operators have progressed from publicly visible disruption of exposed industrial devices to documented extraction and modification of the programs controlling American physical processes.
They are learning.
Defenders should assume that other state actors are learning from the same incidents, just as industrial malware developers studied Stuxnet, the Ukrainian grid attacks and TRISIS. Techniques demonstrated in one geopolitical conflict do not remain confined to the country or actor that first used them.
The necessary alarm
There is a familiar problem in writing about attacks on critical infrastructure.
Describe the worst possibilities too vividly and the result becomes disaster theater: hackers poisoning every reservoir, exploding pipelines and turning off the country with a keystroke. Such stories obscure the engineering difficulties, independent safeguards and operational resilience that stand between access and catastrophe.
Understate the danger and an equally serious distortion occurs. The intrusion is reduced to another item in a vulnerability queue, another set of suspicious IP addresses, another request for a password change.
The July 22 advisory warrants neither panic nor complacency.
It does not establish that Iranian-affiliated operators possess an instant, universal ability to destroy American infrastructure. It establishes something narrower and deeply serious: they have reached real industrial controllers, stolen the programs governing them, altered or deleted operating logic, falsified the information shown to human operators and disabled functions intended to warn of or stop unsafe conditions.
That is not a speculative attack path.
It is an observed intrusion into the mechanisms by which the physical world is controlled.
The appropriate response begins with removing exposed controllers and modems from the public internet. It continues with validating active logic against independently trusted engineering baselines, examining reusable code modules, securing programming modes, inspecting every connected engineering and display system, and ensuring that critical safety decisions do not depend upon a single potentially compromised digital view.
But the deeper response is cultural.
Executives must stop treating operational technology as an obscure technical annex to the corporate network. Engineers must be included in incident planning because cyber responders cannot determine the safety significance of a changed instruction without understanding the process it controls. Cybersecurity teams must learn that restoring a file is not the same as restoring a trustworthy physical state. Boards and public officials must recognize that small utilities and municipalities cannot be expected to defend national infrastructure threats with improvised staffing and aging equipment alone.
The alarm here is not that catastrophe has already occurred.
It is that adversaries have crossed several of the boundaries that once separated a network intrusion from one. They have entered the controller, changed the logic, interfered with the safeguards and begun manipulating the operator’s view of reality.
The machinery may continue running.
The screen may remain green.
That is precisely why the warning must be heard.
Sources
FBI, CISA, NSA, EPA, Department of Energy, U.S. Cyber Command and Department of the Treasury, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” AA26-097A, updated July 22, 2026.
National Institute of Standards and Technology, “Guide to Operational Technology Security,” Special Publication 800-82 Revision 3, September 2023.
U.S. Department of Energy, “Multiyear Plan for Energy Sector Cybersecurity,” 2018.
U.S. Government Accountability Office, “Defense Infrastructure: Improvements in DOD Reporting and Cybersecurity Implementation Needed to Enhance Utility Resilience Planning,” July 2015.
CISA, FBI, NSA, EPA and partner agencies, “IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities,” updated December 2024.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: